FILEMembers
FILE

Expired 2017 Certificate Still Powers Process Hacker 2 Offensive Toolkit

A complete 17-file Process Hacker 2 distribution — including a LOLDrivers-listed kernel driver and thirteen plugin DLLs — is circulating as a staged offensive package under Authenticode signatures expired since January 2017. The expired-but-authentic certificate chain suppresses plugin detections to as low as 5 of 76 AV engines, while embedded sandbox-detection logic and Tor-routed delivery round out a deliberately assembled evasion stack.

May 28, 2026, 22:59 (UTC+9)Last seenMay 29, 2026Severity71ByCTX TeamActorRoyal RansomwareTeam OneIOC19MITRE10

Seventeen Windows executables — two main GUI binaries, a kernel-mode driver, a PE viewer, and thirteen plugin DLLs — have been assembled into a unified offensive package and are circulating with Authenticode signatures that expired in January 2017. The signing identity is "Wen Jia Liu," issued under two DigiCert certificate serials that together bind every file in the toolkit to a single developer lineage.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence